Composer package intelligence
drupal/core Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting the Composer package drupal/core, including the gap beyond CISA KEV, confidence assessments, and sensor observations.
- Total KEVs
- 5
- Known exploited vulnerabilities affecting drupal/core
- In CISA KEV
- 5
- Records also listed in the official catalog
- Beyond CISA KEV
- 0
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 1
- drupal/core KEV with sensor-observed exploitation activity
Review drupal/core exploitation against the versions you run
All five exploited drupal/core vulnerabilities tracked here are also listed in CISA KEV.
- 100%
- Covered by CISA
- 0%
- Beyond CISA
Attested drupal/core vulnerabilities
5 known exploited vulnerabilities affecting this package.
| Vulnerability | CISA KEV | Added |
|---|---|---|
|
CVE-2026-9082
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004 |
In CISA | 01 Jun 2026 |
|
CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an... |
In CISA | 03 Nov 2021 |
|
CVE-2020-13671
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension... |
In CISA | 18 Jan 2022 |
|
CVE-2019-6340
Drupal core - Highly critical - Remote Code Execution |
In CISA | 25 Mar 2022 |
|
CVE-2018-7602
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004 |
In CISA | 13 Apr 2022 |
Recurring weakness patterns
Improper Input Validation, Unrestricted Upload of File with Dangerous Type, and Deserialization of Untrusted Data account for mapped occurrences across this drupal/core KEV portfolio.